Rupee Compass guide
How Rupee Compass Protects Financial Data
A plain-language security guide covering login boundaries, role checks, device safety, encrypted document flows, scoped sharing, audit trails, and incident response.
By Rupee Compass Editorial Team · Published 3 August 2026
Why this matters
A plain-language security guide covering login boundaries, role checks, device safety, encrypted document flows, scoped sharing, audit trails, and incident response.
Where Rupee Compass fits
Starting point: Account boundaries; Manual setup across separate tools Ongoing review: Permission checks; Repeated exports and reconciliation Decision context: Controlled sharing; Context rebuilt for each decision
Financial security starts with account boundaries
Public education can remain open, but transactions, balances, plans, documents, tax tasks, family records, and settings must stay tied to the correct authenticated identity. Backend authorization—not hidden buttons—decides whether a user, share viewer, employee, CA, staff member, or administrator can open a resource. Separate account and organization scopes prevent one person's records from leaking into another workflow.
Protect login and device sessions
Use a unique password, protect the email and phone that receive recovery messages, and never disclose an OTP. Review unfamiliar device or login alerts through official app and support channels. A password manager can help, but recovery secrets should not be copied into an ordinary finance note. Sign out or revoke access on a lost device and update credentials when compromise is plausible.
Treat documents as scoped records
Locker, tax, insurance, identity, and family files can reveal far more than a transaction total. Upload through intended authenticated routes, use meaningful labels, and share only the item needed. Sensitive storage should use encryption and restricted access, while application logs and screenshots should avoid secrets. Delete obsolete copies when retention is no longer justified.
Use permissioned sharing instead of screenshots
Screenshots are permanent, easy to forward, and often expose surrounding data. Share Access can provide a live, scoped view with masking, passcodes, selected documents, and revocation. Verify the recipient, choose the smallest permission, send passcodes separately, and revoke access after the task. Connected Partner is separate and never reveals pages or raw participant records.
Monitor suspicious activity without overclaiming
Rate limits, device signals, failed-login patterns, risky payload detection, security alerts, and audit records help the team detect and investigate abuse. A signal does not automatically prove an attack or a fraudulent transaction. Controls should protect normal users quietly, preserve evidence, and route serious incidents to authorized review without exposing internal security details to untrusted clients.
Know what support will never request
Support may ask for an account email, safe reference, approximate time, app version, and concise problem description. It should not need your password, OTP, complete card number, PIN, or an unrelated financial document. If a request feels unsafe, stop, open the official Contact or Support route yourself, and preserve the suspicious message for review.
Product capabilities covered
- Account boundaries
- Permission checks
- Controlled sharing
- Security monitoring